cbcvebase.
CVE-2025-8225
published 2025-07-27

CVE-2025-8225: A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c…

low1.9CVSS 4.0
AVLACLATNPRLUINVCNVINVALSCNSINSANEPCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.

Affected

17 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.45-3 (forky)binutils 2.45-3 (forky)
gnubinutils
gnubinutils>= 0 < 2.45-32.45-3
gnubinutils>= 0 < 2.38-4ubuntu2.102.38-4ubuntu2.10
gnubinutils>= 0 < 2.38-4ubuntu2.112.38-4ubuntu2.11
gnubinutils>= 0 < 2.42-4ubuntu2.62.42-4ubuntu2.6
gnubinutils>= 0 < 2.42-4ubuntu2.72.42-4ubuntu2.7
gnubinutils>= 0 < 2.45-7ubuntu1.12.45-7ubuntu1.1
gnubinutils>= 0 < 2.24-5ubuntu14.2+esm72.24-5ubuntu14.2+esm7
gnubinutils>= 0 < 2.26.1-1ubuntu1~16.04.8+esm132.26.1-1ubuntu1~16.04.8+esm13
gnubinutils>= 0 < 2.30-21ubuntu1~18.04.9+esm52.30-21ubuntu1~18.04.9+esm5
gnubinutils>= 0 < 2.34-6ubuntu1.11+esm12.34-6ubuntu1.11+esm1
msrcazl3_binutils_2.41-7_on_azure_linux_3.0
msrcazl3_binutils_2.41-9_on_azure_linux_3.0
msrccbl2_binutils_2.37-15_on_cbl_mariner_2.0
msrccbl2_binutils_2.37-16_on_cbl_mariner_2.0
msrccbl2_binutils_2.37-17_on_cbl_mariner_2.0

CVSS provenance

nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv4.8MEDIUM